
Google pauses open-source bug bounty program over invalid reports
Published by AINave Editorial
Google’s open-source bug bounty pause took effect October 1, after what the company called a significant rise in automated submissions. Google said the vast majority of those submissions were not valid. The pause affects its Open Source Software Vulnerability Rewards Program, which paid researchers for finding vulnerabilities in Google’s open-source software.
The problem is review capacity, not just report volume
A larger number of submissions can sound like more security coverage. But a report only helps if someone can verify the issue and determine whether it is a real vulnerability. When most incoming reports are invalid, the review queue itself becomes a cost for the people responsible for handling it.
TechCrunch reported, citing Tom’s Hardware, that invalid reports and reports containing hallucinations overwhelmed Google engineers and open-source maintainers. That account of the operational impact is secondhand; Google’s own stated reason was the rise in automated submissions and their low validity. The distinction matters: the pause shows that submission volume had become a problem for this program, but the available evidence does not quantify how many reports arrived or how much reviewer time they consumed.
For researchers, the practical change is straightforward: submissions to this open-source rewards program are paused. It is a specific program decision, not evidence that Google has shut down all vulnerability reporting or that automated security research has no value. The issue described here is that the reports reaching this program were mostly not valid.
Q1 2027 is an update milestone, not a restart date
Google said it would provide an update in the first quarter of 2027. That is a commitment to communicate about the program, not a promise that submissions will resume then. The company encouraged participants to consider its other bug bounty programs in the meantime, but the available reporting does not establish whether any particular alternative is currently accepting submissions.
That leaves a meaningful gap between the pause and the next stated milestone. Google has not, in the supplied information, described what changes it might make to screening or review, or said when the open-source program will reopen. Until it provides that detail, researchers should treat the pause as ongoing rather than read Q1 2027 as a reopening target.






















